CVE-2025-36565: Medium severity Dell PowerProtect Data Domain vulnerability
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.1.0.10, LTS2024 release Versions 7.13.1.0 through 7.13.1.25, LTS 2023 release versions 7.10.1.0 through 7.10.1.50, contain an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary command execution. Exploitation may allow privilege escalation to root.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-36565?
CVE-2025-36565 has been classified as a high severity vulnerability.
What are the affected versions for CVE-2025-36565?
CVE-2025-36565 affects Dell PowerProtect Data Domain versions between 7.7.1.0 and 8.1.0.10, as well as versions 7.13.1.0 to 7.13.1.25, and 7.10.1.0 to 7.10.1.50.
How do I fix CVE-2025-36565?
To fix CVE-2025-36565, upgrade to the latest patched version of the Dell PowerProtect Data Domain software.
What type of vulnerability is CVE-2025-36565?
CVE-2025-36565 is categorized as an improper neutralization of argument delimiters vulnerability.
What impact does CVE-2025-36565 have on systems?
CVE-2025-36565 may allow an attacker to exploit the system and potentially gain unauthorized access.